Report a vulnerability to the security team

2024-10-03 Thread Daniel Leidert
Hi, I just became aware that a new unbound version was released just now that fixes a vulnerability (CVE-2024-8508) that is not yet listed in the tracker. What are the proceedings to get it listed/evaluated? Regards, Daniel signature.asc Description: This is a digitally signed message part

Re: Report a vulnerability to the security team

2024-10-03 Thread Sylvain Beucler
Hi Daniel, On 03/10/2024 21:47, Daniel Leidert wrote: I just became aware that a new unbound version was released just now that fixes a vulnerability (CVE-2024-8508) that is not yet listed in the tracker. What are the proceedings to get it listed/evaluated? Salvatore just added it :) https://s

(E)LTS report for September 2024

2024-10-03 Thread Adrian Bunk
LTS: booth: - Released DLA-3894-1, fixing CVE-2024-3049. - Provided the package for DSA-5777-1, fixing CVE-2024-3049 in bookworm. nghttp2: - Released DLA-3898-1, fixing CVE-2024-28182. - Submitted a package fixing CVE-2024-28182 in the next bookworm point release. php-twig: - Released DLA-38